Bank-Impersonation Wire Transfer Request: Which Attack Is It?
A company's accounting department receives an urgent payment message from the company's bank domain with instructions to wire transfer funds. The sender requests that the transfer be completed as soon as possible. Which of the following attacks is described?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can separate the named fraud campaign (BEC) from the generic technique labels, and the trap is picking 'Impersonation' or 'Spear phishing' because both accurately describe part of what the attacker did.
An urgent wire-transfer instruction that appears to come from the company's own bank is a business email compromise (BEC) — a finance-targeted social-engineering fraud, not generic vishing or spear phishing. This page confirms why option A is the SY0-701 answer and why impersonation is only the mechanism behind it.
Selecting D. Impersonation because the sender spoofs the bank's domain, or C. Spear phishing because the message is targeted; both describe the mechanism or delivery channel, while the scenario's bank-plus-accounting-plus-wire-transfer objective matches CompTIA's definition of business email compromise.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario stacks the three hallmarks CompTIA attaches to business email compromise: a trusted external identity (the company's bank domain), a finance function as the target (accounting), and manufactured urgency pushing an outbound wire transfer. As iliecomptia points out, the study guide describes BEC as "BEC= An impersonation attack in which the attacker gains control" — the fraud is the purpose of the attack, not the phishing mechanics that deliver it. Anyio reaches the same conclusion, noting that in BEC "attackers impersonate a trusted entity (e.g., a bank or executive)" to trick victims into performing a financial transaction. Because the requested action is an irrevocable money movement to an attacker-controlled account, SY0-701 labels this BEC (also called email account compromise) rather than a generic phishing category. The learner vote record is unanimous on A, which matches the exam blueprint's treatment of this exact fraud pattern.Why the Other Options Are Wrong
B. Vishing requires a voice channel — a phone call, voicemail, or VoIP lure — and nothing in the scenario describes spoken contact; the lure arrives as a written payment message. C. Spear phishing describes targeted credential harvesting or malware delivery against a specific group, which is the delivery technique rather than the wire-fraud objective; jennyka76 lists CEO fraud and bank transfer fraud as spear-phishing examples, but the exam blueprint files bank-transfer fraud squarely under BEC. D. Impersonation is genuinely present — an attacker is posing as the bank — but it is the umbrella term covering helpdesk calls, badge cloning, and vendor spoofing alike, so it is the second-best answer rather than the best one. jbmac's observation that a BEC attacker "impersonates a high-level executive, a trusted vendor" shows how the impersonation label gets absorbed once a more specific named attack fits.Community Comment Notes
The community is effectively unanimous here, with 89 votes on A and no dissent beyond one learner choosing C. iliecomptia anchors the answer in the official study guide wording rather than intuition, which is exactly how this question should be reasoned. Anyio breaks the definition into its parts — impersonated trusted entity plus a financial transaction — and jbmac adds the insider detail of targeting the accounting department. jennyka76's vote for spear phishing is a useful reminder that the categories overlap, but that overlap is precisely why the exam expects the most specific named attack that matches the outcome.Official Reference
Exam Strategy
When one option names a specific fraud campaign (BEC) and another names only the underlying technique (impersonation, spear phishing), choose the specific campaign that matches the requested action and victim group. Anchor your decision on the money movement and the finance-department target, not on the fact that the sender address was spoofed. Reading for keywords like 'urgent', 'wire transfer', and 'bank domain' will point you to BEC every time on SY0-701.
Frequently Asked Questions
Why isn't impersonation (D) the best answer if the sender spoofed the bank?
Impersonation is only the mechanism; SY0-701 wants the named attack that matches the finance-fraud outcome, and BEC is the specific label for bank or executive spoofing that drives wire transfers.
How does BEC differ from spear phishing in this bank wire scenario?
Spear phishing is the delivery method aimed at specific users, while BEC is the goal-oriented fraud — convincing accounting to send funds to an attacker-controlled account.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →